unphish
unphish unphish

What Sits Behind a Fake Gambling Website?

What Sits Behind a Fake Gambling Website?

When a website is found impersonating a wagering brand, the copied logo and branding are often the most obvious signs of abuse. But they are only part of what can be investigated.

During our monitoring, we identified a website using the branding of a major international wagering operator. Hosted on [redacted]358.com, the site went beyond a copied landing page, presenting visitors with casino games, account registration, promotions, VIP rewards, customer support and detailed policy information.

Rather than stopping at the impersonation itself, we looked further into how the website operated and the infrastructure behind it.

What we found showed why determining whether a wagering website is legitimate isn’t always as straightforward as checking the domain name. Legitimate operators can use multiple domains and rely on third-party technology to deliver their services, meaning some of the features that appear unusual at first can also be found across legitimate wagering websites. The differences only became clearer as we looked further beneath the surface.

More Than a Copied Homepage

The website at [redacted]358.com went well beyond a simple page displaying copied branding. Visitors could navigate through what appeared to be a complete online casino, with a large library of games, account registration, promotions, a VIP program, customer support and dedicated pages covering privacy, responsible gambling, AML and KYC requirements. Some of the casino games could also be launched directly from the website in demo mod

The impersonating website presented a complete casino environment using copied branding

(The impersonating website presented a complete casino environment using copied branding.)

With so much functionality sitting behind the homepage, one of the first places we looked was the domain itself.

[redacted]358.com was different from the operator’s primary website and combined the brand name with a series of numbers. On its own, that might appear to be an obvious sign that something wasn’t right. However, our investigation found that the legitimate operator also uses alternative domains following a similar numbered format.

We examined one of these legitimate domains, [redacted]1071.com. A WHOIS lookup showed that it was registered to an organisation associated with the operator and used the same registrar as the operator’s primary website. When accessed from Australia, it also behaved consistently with the primary website, displaying the same regional restriction.

This meant the numbered format alone wasn’t enough to distinguish the impersonating website from a legitimate one. [redacted]358.com followed a naming pattern that could also be found within the operator’s genuine domain portfolio.

The differences became more apparent when we compared how the websites actually behaved and looked beyond the names in the address bar.

Comparing the Websites

While the domain name alone did not provide a super clear distinction, the way the websites behaved did.

When accessed from Australia, both the operator’s primary website and the legitimate numbered domain displayed a regional restriction explaining that players from Australia could not be accepted. The impersonating website did not apply the same restriction. From the same location, visitors could browse the casino, view promotions and VIP offers, access registration and launch games.

Other differences appeared as we moved through the site. Although much of the surrounding interface was presented in English, the customer support widget displayed Russian text, while parts of the VIP program used Russian roubles. One of the casino games we launched also appeared entirely in Russian.

Russian-language customer support service

(Russian-language customer support service.)

Further inspection showed that this was not simply a language setting selected by our browser. The game session itself had been configured to launch in Russian and use RUB as its currency, despite the surrounding website being presented primarily in English.

These details do not establish who was operating the website or where they were located. Language and currency settings can be configured for many reasons. But alongside the different geographic restrictions, they showed that the impersonating website was behaving very differently from the legitimate sites it was attempting to resemble.

The functioning casino games also raised another question. Were they simply legitimate third-party games embedded within an impersonating website, or was there more sitting behind them?

Looking Behind the Games

The casino games offered another area to investigate. Seeing games from third-party providers on a wagering website is not unusual, and [redacted]358.com displayed titles carrying the branding of established game developers.

One of these was Sweet Bonanza 1000, a Pragmatic Play title that could be launched directly from the website in demo mode. On the surface, the game appeared functional, allowing a visitor to spin and receive results as they would expect from a casino game.

(The impersonating website presented what appeared to be a Pragmatic Play game directly within its casino environment.)

(The impersonating website presented what appeared to be a Pragmatic Play game directly within its casino environment.)

We inspected the network activity generated when the game was loaded and played. Rather than seeing the game served directly from the third-party provider’s infrastructure, the game files were being delivered through an API associated with [redacted]358.com. When we performed a demo spin, the request was also sent to the same infrastructure, which returned the result of the spin and updated the demo balance.

(Game requests were directed through infrastructure associated with the impersonating domain.)

(Game requests were directed through infrastructure associated with the impersonating domain.)

The game’s spin action was processed through the same API infrastructure

(The game’s spin action was processed through the same API infrastructure.)

The technical configuration provided another clue from earlier in the investigation. The game session had been explicitly set to Russian and configured to use Russian roubles, explaining why Sweet Bonanza 1000 appeared in Russian despite much of the surrounding website being presented in English.

Our investigation therefore indicated that the site was serving its own copy or implementation of a game carrying Pragmatic Play branding, rather than simply loading the game directly from the provider. Without confirmation from the game provider, we cannot determine whether that implementation was authorised.

For a visitor, however, none of this was visible. The game looked familiar, carried the expected branding and could actually be played in demo mode. It was only by looking at the network activity behind the game that the underlying infrastructure became apparent.

Real Company Details, Another Domain

The website’s footer added another layer of apparent legitimacy. It listed the name, registration number and registered address of the wagering operator’s real corporate entity, alongside information about its payment agents and responsible gambling.

The impersonating website displayed genuine corporate information, but directed users to a support email on a separate domain.)

(The impersonating website displayed genuine corporate information, but directed users to a support email on a separate domain.)

Those details were not made up. A search of the relevant corporate register confirmed that the company and registration number were genuine, while the same corporate information also appeared on the legitimate operator’s website.

But genuine company information does not make the website displaying it genuine. Corporate details can be copied just as easily as logos, imagery and other website content.

The contact information provided a more useful lead. While the legitimate operator uses an email address on its primary domain, the impersonating website directed users to a support address ending in [redacted].cc.

We investigated that domain separately. WHOIS records showed it had been registered in February 2026, several months before [redacted]358.com, and through the same registrar. Interestingly, the support domain was also updated on 24 July 2026, the same date [redacted]358.com was registered.

(The support domain was updated on the same day the impersonating domain was registered, with both using the same registrar.)

(The support domain was updated on the same day the impersonating domain was registered, with both using the same registrar.)

At the time of our investigation, the support domain was under Client Hold status and did not resolve when accessed directly. The use of the same registrar and timing of the records do not establish common ownership on their own. However, there was a direct connection between the two domains: [redacted]358.com itself instructed users to contact an email address hosted on the second domain.

Following that contact information gave us another piece of infrastructure associated with the impersonating website and showed why apparently legitimate corporate details should not be taken at face value.

Looking Beyond the Impersonation

At first glance, [redacted]358.com was clearly impersonating an established wagering brand. But determining exactly what sat behind the website required looking beyond the copied branding.

The investigation uncovered several layers. The domain name itself was not enough to distinguish the site from legitimate alternatives used by the operator. Genuine corporate information had been copied into the footer. A recognisable casino game appeared to function normally, despite its gameplay being processed through infrastructure associated with the impersonating domain. The support address then led to a second domain with its own registration history.

None of these findings on their own tells the whole story. Together, they provide a much clearer picture of how the website was operating and the infrastructure connected to it.

For wagering operators, this is why detecting an impersonating domain is only the beginning. Investigating the domains, infrastructure, content and other artefacts associated with a threat can help identify connections that may otherwise be missed and provide stronger evidence for enforcement.

unphish’s threat intelligence showing how threats are connected

(Campaign Clustering & Intelligence helps connect related threats, brands and infrastructure.)

unphish combines continuous threat monitoring, investigation and enforcement with Campaign Clustering & Intelligence to help organisations identify connections between related threats and disrupt the wider activity behind them.

Contact us to learn more about protecting your brand online.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account